Policies and Standards
Information Security is responsible for developing and maintaining technology policies, standards, and guidelines that ensure the security and integrity of the university's information systems and data. These policies establish the foundation for a secure computing environment, aligning with regulatory requirements, industry best practices, and institutional needs.
Policies
Our policies provide the overarching principles and mandatory requirements that all university members must follow to protect institutional data and IT resources. Key policies include:
- Acceptable Use - Employee
- Acceptable Use - Student
- Acceptable Use - Vendor
- Access Control Policy
- Asset Management Policy
- Cellular Device Policy
- Change Management Policy
- Copyright Infringement and Illegal File Sharing
- Cloud Storage
- Data Access, Usage and Sharing
- Data Classification
- Data Encryption Policy
- Data Governance Policy
- Data Integrity and Integration
- Electronic Communications Policy
- Information Security Policy
- Network Policy
- Records Management, Retention, and Disposition Policy
- Security Awareness and Training Policy
- Website Privacy Policy
Standards and Guidelines
In addition to policies, Information Security publishes technical standards and guidelines that detail specific security controls and implementation requirements. These guidelines and standards can be accessed through our Technology Standards and Guidelines site.
Compliance and Enforcement
All university members are expected to adhere to these policies and standards. Non-compliance may result in disciplinary action, loss of access privileges, or other corrective measures. OIS regularly reviews and updates these policies to reflect emerging threats, regulatory changes, and technological advancements.
